Join us to hear stories from the Microsoft Threat Intelligence community as they navigate the ever-evolving threat landscape - uncovering APTs, cybercrime gangs, malware, vulnerabilities, and other weird and cool tools and tactics in the world of cyber threats. Featuring tales of innovation, teamwork, and cyber espionage, tune in to hear in-depth analyses of Microsoft's influence on the threat landscape and behind the scenes stories from the tireless researchers and analysts that take part. This enthralling and insightful podcast is delivered in a casual, conversational style that transports you to the frontlines of cyber defense.
Site
RSS
Apple
Data updated on 28/08/2026
Recent rankings
Latest chart positions across Apple Podcasts and Spotify rankings.
Shared links between episodes and podcasts
Links found in episode descriptions and other podcasts that share them.
Discover shows related to Microsoft Threat Intelligence Podcast, based on actual content similarities. Explore podcasts with similar topics, themes, and formats, backed by real data.
Whisper Leak: How Threat Actors Can See What You Talk to AI About
Season 1 · Episode 59
Wednesday, December 17, 2025 • Duration 47:44
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by security researchers Geoff McDonald and JBO to discuss Whisper Leak, new research showing that encrypted AI traffic can still unintentionally reveal what a user is asking about through patterns in packet size and timing.
They explain how LLM token streaming enables this kind of side-channel attack, why even well-encrypted conversations can be classified for sensitive topics, and what this means for privacy, national-level surveillance risks, and secure product design. The conversation also walks through how the study was conducted, what patterns emerged across different AI models, and the steps developers should take to mitigate these risks.
In this episode you’ll learn:
Why packet sizes and timing patterns reveal more information than most users realize
How user-experience choices like showing streamed text create a larger attack surface
The difference between classic timing attacks and the new risks uncovered in Whisper Leak
Resources:
View JBO on LinkedIn
View Geoff McDonald on LinkedIn
View Sherrod DeGrippo on LinkedIn
Learn more about Whisper Leak
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.
The Grid, a Digital Frontier: E-ISAC on Securing the Power Grid
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Matt Duncan, Vice President of Security Operations and Intelligence at the North American Electric Reliability Corporation’s E-ISAC, to explore the cyber threats targeting the North American power grid. Matt breaks down why the grid remains resilient despite increasing pressure from nation-states, cybercriminals, and hacktivists, how AI is lowering the barrier of entry for attackers, and why OT systems and interconnected devices present unique risks.
He also highlights real success stories, the value of large-scale grid exercises, and how strong collaboration and a focus on foundational security practices help defenders keep power flowing safely and reliably.
In this episode you’ll learn:
How severe weather events trigger heightened cyber-readiness across utilities
What motivates hacktivist groups and how their tactics differ from other threat actors
Why outdated equipment and legacy systems remain such attractive targets
Some questions we ask:
Are you seeing more educated and capable OT-focused adversaries now?
How do you work with policymakers to help them understand these threats?
If you could eliminate one misconception about securing the grid, what would it be?
Resources:
View Matt Duncan on LinkedIn
View Sherrod DeGrippo on LinkedIn
Learn more about E-ISAC
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.
Ahoy! A Tale of Payroll Pirates Who Target Universities
Season 1 · Episode 57
Wednesday, November 19, 2025 • Duration 31:36
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by security researchers Tori Murphy and Anna Seitz to unpack two financially motivated cyber threats. First, they explore the Payroll Pirates campaign (Storm 2657), which targets university payroll systems through phishing and MFA theft to reroute direct deposits. Then, they examine Vanilla Tempest, a ransomware group abusing fraudulent Microsoft Teams installers and SEO poisoning to deliver the Oyster Backdoor and Recita ransomware.
Together, they discuss how attackers exploit trust in identity, code signing, and SaaS platforms and share practical steps organizations can take to strengthen defenses, from phishing-resistant MFA to stricter executable controls and out-of-band banking verification.
In this episode you’ll learn:
How Payroll Pirates diverted university salaries through SaaS HR phishing schemes
Why universities are prime targets for identity-based cyberattacks
How Vanilla Tempest evolved from basic ransomware to complex multi-stage attacks
Some questions we ask:
How are attackers stealing credentials and paychecks?
Why do attackers create inbox rules after compromising accounts?
What alerts should organizations monitor for these types of attacks?
Resources:
View Tori Murphy on LinkedIn
View Anna Seitz on LinkedIn
View Sherrod DeGrippo on LinkedIn
Investigating targeted “payroll pirate” attacks affecting US universities
Microsoft Threat Intelligence healthcare ransomware report highlights need for collective industry action
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.
Beyond AI for Security Hype: What Really Matters in Cyber Defense
Season 1 · Episode 56
Wednesday, November 5, 2025 • Duration 42:05
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Zack Korman, CTO of cybersecurity startup Pistachio. They explore the reality of AI in security, cutting through hype to discuss where AI is both brilliant and flawed, how vendors AI-wash outdated tech, and why Zack believes AI won’t replace jobs but instead scale human creativity. They also dive into phishing simulations, human psychology behind social engineering, AI-powered attacks, jailbreak chaining between AI systems, and the future risks and opportunities AI introduces in cybersecurity.
In this episode you’ll learn:
How to evaluate whether a vendor is truly using AI in their product
The psychology behind why people fall for phishing attacks
Why human judgment will remain essential in the era of AI-driven security.
Some questions we ask:
How can AI unlock new capabilities in cybersecurity?
What questions should people ask AI security vendors?
Why do trained security professionals still fall for phishing attacks?
Resources:
View Zack Korman on LinkedIn
View Sherrod DeGrippo on LinkedIn
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.
The New Frontlines of Cybersecurity: Lessons from the 2025 Digital Defense Report
Season 1 · Episode 55
Wednesday, October 22, 2025 • Duration 47:29
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Chloé Messdaghi and Crane Hassold to unpack the key findings of the 2025 Microsoft Digital Defense Report; a comprehensive look at how the cyber threat landscape is accelerating through AI, automation, and industrialized criminal networks.
They explore how nation-state operations and cybercrime have fused into a continuous cycle of attack and adaptation, with actors sharing tooling, infrastructure, and even business models. The conversation also examines AI’s growing impact, from deepfakes and influence operations to the defensive promise of AI-powered detection, and how identity compromise has become the front door to most intrusions, accounting for over 99% of observed attacks.
Listeners will gain perspective on:
How AI is shaping both attacker tradecraft and defensive response.
Why identity remains the cornerstone of global cyber risk.
What Microsoft’s telemetry—spanning 600 million daily attacks—reveals about emerging threats and evolving defender strategies.
Questions explored:
How are threat actors using AI to scale deception and influence operations?
What does industrialized cybercrime mean for organizations trying to defend at scale?
How can defenders harness AI responsibly without overreliance or exposure?
Resources:
Download the report and executive summary
Register for Microsoft Ignite
View Chloé Messdaghi on LinkedIn
View Crane Hassold on LinkedIn
View Sherrod DeGrippo on LinkedIn
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.
Threat Landscape Update: Ransomware-as-a-Service and Advanced Modular Malware
Season 1 · Episode 54
Wednesday, October 8, 2025 • Duration 30:31
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Tori Murphy, Anna Seitz, and Chuong Dong to break down two threats: the modular backdoor PipeMagic and Medusa ransomware. They discuss how PipeMagic disguises itself as a ChatGPT desktop app to deliver malware, its sophisticated modular design, and what defenders can do to detect it.
The team also explores Medusa’s evolution into a ransomware-as-a-service model, its use of double extortion tactics, and the broader threat landscape shaped by ransomware groups, social engineering, and the abuse of legitimate tools.
In this episode you’ll learn:
Why modular malware is harder to detect and defend against
How attackers abuse vulnerable drivers to disable security tools
Why leak sites play a central role in ransomware operations
Some questions we ask:
How did Microsoft researchers uncover PipeMagic in the wild?
Why do ransomware groups often borrow names and themes from mythology?
What initial access techniques are commonly associated with Medusa attacks?
Resources:
View Anna Seitz on LinkedIn
View Chuong Dong on LinkedIn
View Sherrod DeGrippo on LinkedIn
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.
Stopping Domain Impersonation with AI
Season 1 · Episode 53
Wednesday, September 24, 2025 • Duration 26:00
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Kelly Bissell, Corporate Vice President at Microsoft, to explore how domain impersonation and typosquatting are changing in the age of AI.
They discuss how attackers are increasingly using AI and bots to scale online deception, why this tactic is so effective, and how Microsoft is countering cutting-edge defenses like Siamese neural networks to detect fraudulent domains in real time. Kelly shares insights on the massive scale of these threats, the shift toward defender advantage, and the broader implications for securing organizations worldwide.
In this episode you’ll learn:
How attackers use AI and bots to scale domain impersonation and typosquatting
Why defenders may finally have the higher ground in the fight against online fraud
How Microsoft’s Siamese neural network model detects fraudulent domains in real time
Some questions we ask:
What excites you most about this new detection approach?
How do fake domains fit into a larger social engineering chain?
What indicators should defenders watch for in typosquatting domains?
Resources:
View Kelly Bissell on LinkedIn
View Sherrod DeGrippo on LinkedIn
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
Click, Call, Compromise: Inside the Latest Loader Campaigns
Season 1 · Episode 52
Wednesday, September 10, 2025 • Duration 28:58
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Microsoft researchers Kelsey Clapp and Anna Seitz to examine two major cybercrime campaigns. The team unpacks Storm 2561’s use of SEO poisoning to distribute Trojanized software like SilentRoute and Bumblebee, stealing VPN credentials and paving the way for ransomware brokers.
They also dive into Storm 1811’s ReadBed malware, a loader deployed through bold social engineering tactics, such as fake IT help desk calls via Teams, that enable lateral movement and ransomware deployment. The discussion highlights how modern threat actors exploit trust, extend attack chains, and continually evolve their techniques, underscoring the importance of vigilance, strong security controls, and verifying before trusting.
In this episode you’ll learn:
How Storm 2561 uses SEO poisoning to trick users into downloading Trojanized software
The role of trust, urgency, and habit in social engineering tactics
Practical steps organizations can take to block these threats and strengthen defenses
Some questions we ask:
Why are initial access loaders such a big risk for organizations?
How are threat actors using fake IT help desk calls to gain access?
What steps should defenders take to cut off these entry points?
Resources:
View Anna Seitz on LinkedIn
View Kelsey Clapp on LinkedIn
View Sherrod DeGrippo on LinkedIn
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.
Live from Black Hat: Ransomware, Responsible Disclosure, and the Rise of AI
Season 1 · Episode 51
Wednesday, August 27, 2025 • Duration 43:56
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is live from Black Hat 2025 with a special lineup of Microsoft security leaders and researchers.
First, Sherrod sits down with Tom Gallagher, VP of Engineering and head of the Microsoft Security Response Center (MSRC). Tom shares how his team works with researchers worldwide, why responsible disclosure matters, and how programs like Zero Day Quest (ZDQ) are shaping the future of vulnerability research in cloud and AI security. He also announced the next iteration of ZTQ with $5 million up for grabs.
Next, Sherrod is joined by Eric Baller (Senior Security Researcher) and Eric Olson (Principal Security Researcher) to unpack the fast-changing ransomware landscape. From dwell time collapsing from weeks to minutes, to the growing role of access brokers, they explore how attackers operate as organized ecosystems and how defenders can respond.
Finally, Sherrod welcomes Travis Schack (Principal Security Researcher) alongside Eric Olson to examine the mechanics of social engineering. They discuss how attackers exploit urgency, trust, and human curiosity, why AI is supercharging phishing campaigns, and how defenders can fight back with both training and technology.
In this episode you’ll learn:
How MSRC partners with researchers across 59 countries to protect customers
Why Zero Day Quest is accelerating vulnerability discovery in cloud and AI
How ransomware dwell times have shrunk from days to under an hour
Resources:
View Sherrod DeGrippo on LinkedIn
Zero Day Quest — Microsoft
Microsoft Security Response Center Blog
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.
How Microsoft Stays Ahead of the World’s Most Dangerous Hackers
Season 1 · Episode 50
Thursday, August 7, 2025 • Duration 01:17:33
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Aarti Borkar, Simeon Kakpovi, and Andrew Rapp for a behind-the-scenes look at how Microsoft Threat Intelligence and Microsoft Incident Response teams collaborate as part of a closed-loop system, the emotional toll of breaches, and how organizations of any size can build resilience through preparation and psychological safety. By listening to this segment, you’ll get a preview of what this group brought to the main stage of Black Hat this year.
Later, Sherrod chats with Snow, co-founder of the Social Engineering Community Village at DEF CON, about her journey from special effects makeup to elite social engineer, and how empathy, creativity, and even a ladder can be powerful tools in physical security testing.
In this episode you’ll learn:
How Microsoft’s Digital Crimes Unit uses legal tactics to disrupt threat actors
Why rehearsing your incident response plan can save weeks of recovery time
How AI is being trained to make social engineering phone calls on its own
Some questions we ask:
How would you describe the overall health of the global cybersecurity landscape?
Why does tailoring AI prompts sometimes feel like social engineering?
What is the feedback loop between incident response, intelligence, and product protections?
Resources:
View Aarti Borkar on LinkedIn
View Simeon Kakpovi on LinkedIn
View Andrew Rapp on LinkedIn
View Sherrod DeGrippo on LinkedIn
Microsoft at Black Hat USA 2025
Related Microsoft Podcasts:
Afternoon Cyber Tea with Ann Johnson
The BlueHat Podcast
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.